Security1 distinct publisher2 min readPublished
Comparitech's half-year tally shows government ransomware growing again, with the newest crew on the board, The Gentlemen, out-filing Qilin and spreading its targeting well beyond the United States.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Comparitech got confirmation from the victim in 89 of the 187 cases [3], a 47.6% confirmation rate [2], with 98 claims resting only on what the gang said [3] -- nearly half the count is leak-site bookkeeping. The Gentlemen's ledger holds up better than most of the field: 10 of its 22 claims were confirmed [7], 45% [12]. Qilin confirmed 9 of 21, LockBit 7 of 14, INC 6 of 10 [6][7]. Taken together, the top five strains account for 79 of the 187 claims, 42% of the half-year [4].
Median demands fell 80% [5] while the attack count rose 13.3% [1], pricing running opposite to volume. That is a smaller ask spread across more victims, and the half-year record holds too few confirmed payments to show whether it converts better.
Comparitech puts known records breached in confirmed attacks at just under 179,000 [13]; Suffolk, Virginia accounts for 157,725 of them [14], 88% [7] -- the breach total is essentially one city. The three largest known breaches together cover 173,921 people, leaving roughly 5,000 across every other confirmed attack in the period [8]. Suffolk is also the case worth reading closely: the attack was stopped before ransomware was deployed, and Cloak still claimed 2.5 TB of stolen data [14].
Government agencies take about four months on average to notify breach victims [17], all three of the largest H1 breaches date to Q1 [17], and last month the City of Middletown, Ohio began notifying 123,791 people about a July 2025 incident [18], a single 2025 attack equal to 69% of the entire H1 2026 figure [9] -- so that 179,000 figure will grow.
Comparitech attributes part of the US decline to The Gentlemen not concentrating inside the US the way Qilin has [10]. Strain-level movement is consistent with that reading: Qilin claims against government targets fell 45% while LockBit's rose 250% [8]. The researchers also flag that this sector report was compiled after their general H1 2026 report, so the numbers may shift as more attacks are confirmed [21].
Ranked by verification strength, evidence, and original report placement.
Attacks on government agencies attributed to The Gentlemen rose from a single attack in H2 2025 to 22 in H1 2026.
The Gentlemen only emerged in September 2025.
All of the largest H1 2026 government breaches stem from Q1 2026, and it takes an average of about four months for most government agencies to notify victims of data breaches.
Comparitech researchers logged 187 ransomware attacks on government entities from January to June 2026, an average of one attack per day.
The H1 2026 total of 187 attacks was up by over 13 percent compared with H2 2025, when Comparitech logged 165 attacks on government entities.
Of the 187 attacks recorded in H1 2026, 89 were confirmed by the targeted entities and 98 were unconfirmed.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric3 distinct publishers
security
CRPx0 climbed to 46 claimed victims in July on countdowns that fired in near unison1 distinct publisher
security
FBI counts 30-plus ransomware disruptions this year, and the target is the plumbing1 distinct publisher
security
Mexico's cyber plan puts the phone number in 2026 and the scoreboard in 20301 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One tracker, half the incidents unattested
Every figure in this story — 187 attacks, the 13 percent rise, the $100,000 median — comes from Comparitech's own monitoring, and nobody in this reporting has checked it against another count. To the firm's credit it publishes the split: 89 of the 187 were acknowledged by victims, which leaves 98 resting on what the gangs posted about themselves, and criminal leak sites are marketing. The named cases are solid ground; the aggregate is an estimate wearing a precise number.
Real damage, documented case by case
The confirmed column is what lifts this above leak-site noise: a Virginia city writing to 157,725 people, a Turkish parking authority conceding 10,000, a Minnesota county mailing 6,196, a German transit operator dark for eleven weeks, one county admitting it paid $200,000. That is measurable harm, not a projection. It is also a thin base for a global picture — three incidents carry 173,921 of the roughly 179,000 known victims, and the rest of the confirmed attacks together account for about five thousand.
Headline outruns its own numbers
'Once a day' is arithmetically fair and rhetorically generous, since it counts 98 attacks only the attackers have vouched for. And the report's own data argues against the escalation reading: US government incidents down 23 percent, the median demand collapsing from $500,000 to $100,000, Q2 dipping. The Gentlemen 'dominating' comes with Comparitech's own asterisk — the group barely existed during the period it is being compared against.
The counter is also the commentator
Comparitech produces the count, interprets it, and repeats the exercise every six months — the piece cross-refers to its earlier report and footnotes that this sector edition was written afterwards. A recurring research franchise built on half-year totals has an obvious pull toward growth framing, and 'attacks up 13 percent' travels further than 'demands down 80 percent'. The offsetting signal is that this edition prints the declines, the unconfirmed share and the provisional caveat instead of burying them.
Trust the named victims, hold the totals loosely
Where an entity spoke for itself the reporting is firm: Suffolk's notification count, Murray County's payment, Latvia's forestry service naming a two-year-unpatched system. The half-year aggregates deserve wider error bars — one tracker, self-declared provisional, almost half its incidents unconfirmed, and a notification lag long enough to guarantee the H1 breach total climbs. Middletown makes the point: a single late disclosure from July 2025 was larger than two thirds of everything counted for this half-year.